Ad Schellevis
83bdc4b47e
MVC, optionally allow dynamic interfaces for InterfaceField, ref https://github.com/opnsense/core/issues/2332
2019-03-06 13:23:04 +01:00
Ad Schellevis
2c2eca7e2f
OpenVPN server, support static-challenge formatted password, closes https://github.com/opnsense/core/issues/3290
2019-03-06 10:20:02 +01:00
Ad Schellevis
a98f04372f
bit of a hack for https://github.com/opnsense/core/pull/3234
2019-03-05 19:35:47 +01:00
Fabian Franz BSc
36ea41ae68
core/vpn/ipsec: allow easier override of colors in themes ( #3286 )
2019-03-05 18:44:39 +01:00
Ad Schellevis
569abf9ac6
fix https://github.com/opnsense/core/pull/3234
2019-03-05 18:42:18 +01:00
Franco Fichtner
27d606474f
system: add phpseclib dependency and enable it
2019-03-05 17:20:10 +00:00
Ad Schellevis
ee8fd03c33
IPSec / routed (VTI), we shouldn't add route-to rules for ipsec interfaces, but the same likely counts for all that's plugged in automatically. for https://github.com/opnsense/core/issues/2332
2019-03-05 17:04:22 +01:00
Ad Schellevis
139ef623dc
IPSec / routed (VTI), fix previous, https://github.com/opnsense/core/issues/2332
2019-03-05 15:59:17 +01:00
Ad Schellevis
77743cfc09
IPSec / routed (VTI), create virtual terminal interfaces for https://github.com/opnsense/core/issues/2332
...
- ipsec_configure_vti() synchronizes local configuration with current ipsec% interfaces
- ipsec_interfaces() automatically adds these interfaces to the interfaces list, so the user can add a gateway and routes
2019-03-05 15:27:54 +01:00
Ad Schellevis
8a55989d3b
Interfaces, parse tunnel endpoints in legacy_interfaces_details(), required for https://github.com/opnsense/core/issues/2332
2019-03-05 11:44:49 +01:00
Ad Schellevis
858f68d7b9
IPsec, while working on https://github.com/opnsense/core/issues/2332 found some weirdness around ipsec_get_phase1_src()
...
both get_interface_ipv6() and get_interface_ip() call get_failover_interface() which obscures the used parameters a lot (wan,lan,opt1 vs emX,emY,igbX)
2019-03-05 11:38:42 +01:00
Franco Fichtner
a6de9b245e
system: sync include paths for PHP
...
/usr/local/share is for phpseclib and it should always be
reachable.
2019-03-05 11:28:44 +01:00
Franco Fichtner
2a910e797a
system: bump syslog version
2019-03-05 08:04:28 +01:00
Björn Kalkbrenner
8e361f3051
dhcp: added TFTP bootfile-name
...
PR: https://github.com/opnsense/core/pull/3074
2019-03-05 07:11:55 +01:00
Ad Schellevis
d9dbcaf052
IPSec / routed (VTI). add tunnel settings to phase2, https://github.com/opnsense/core/issues/2332
2019-03-04 19:41:44 +01:00
Ad Schellevis
a045d3e9f6
IPSec / routed (VTI), when auto_routes_disable is set, set auto = start in stead of route, for https://github.com/opnsense/core/issues/2332
2019-03-04 16:10:09 +01:00
Ad Schellevis
4c3d069ca4
IPSec / routed (VTI), make sure all connections use predefined reqid, for https://github.com/opnsense/core/issues/2332
...
it would be good to refactor this code at some point, maybe wrap some of its logic in a class.
There's just too much logic in ipsec_configure_do at the moment
2019-03-04 15:43:08 +01:00
Ad Schellevis
9ccabe68a6
IPsec / routed (VTI), make installpolicy optional, for https://github.com/opnsense/core/issues/2332
2019-03-04 14:10:05 +01:00
Ad Schellevis
a5f4d1c0ec
configd + python3, missing decode() in _encode_idna, dumping byte output in stead of string
2019-03-04 13:55:59 +01:00
Franco Fichtner
1f41c14ce9
pkg: fix plist
2019-03-04 13:13:23 +01:00
Franco Fichtner
b24725c6da
system: tweak previous, same file suffix, ordering
2019-03-04 13:12:54 +01:00
Franco Fichtner
7a40a22c2a
system: small tweaks to auth templates
2019-03-04 12:58:11 +01:00
Ad Schellevis
060a3e2cbf
IPsec+pam, forgot to add the template, for https://github.com/opnsense/core/issues/3265
2019-03-04 12:30:18 +01:00
Franco Fichtner
80feeafa46
unbound: remove debug output #3260
2019-03-04 07:29:32 +01:00
Franco Fichtner
6d66dd81b2
system: avoid short PHP tag
2019-03-04 07:24:31 +01:00
Ad Schellevis
7943492d84
configd, logging, align message string entries with parameters, closes https://github.com/opnsense/core/issues/3271
2019-03-03 18:08:47 +01:00
Franco Fichtner
7e7f432b72
unbound: add aliases to listing; closes #3260
2019-03-03 11:11:47 +01:00
Franco Fichtner
7ee5ed2a43
www: style updates
2019-03-03 10:44:38 +01:00
Franco Fichtner
0e407b1215
firmware: finally revoke 18.7 fingerprint
2019-03-01 19:06:46 +01:00
Franco Fichtner
0242bac1f9
src: style sweep
2019-03-01 19:02:32 +01:00
Michael
c8840c3e89
Proxy: add auth to parent proxy ( #3269 )
2019-03-01 18:45:59 +01:00
Ad Schellevis
f685abcc9c
Trust/cert, disable https://github.com/opnsense/core/pull/3234 until @fichtner adds phpseclib
2019-03-01 18:39:07 +01:00
Ad Schellevis
e65669383d
Trust/cert, cleanup sign_cert_csr type
2019-03-01 18:36:44 +01:00
Ad Schellevis
2f919443dc
cherry-pick https://github.com/opnsense/core/pull/3234
2019-03-01 18:35:50 +01:00
Ad Schellevis
e505fe0374
Merge branch 'MichaelDeciso-reorder-log-settings'
2019-03-01 15:06:29 +01:00
Ad Schellevis
be93dfcabb
Merge branch 'reorder-log-settings' of https://github.com/MichaelDeciso/core into MichaelDeciso-reorder-log-settings
2019-03-01 15:06:13 +01:00
Ad Schellevis
3d07a9eb77
minor cleanups, closes https://github.com/opnsense/core/pull/3112
2019-03-01 14:55:36 +01:00
Ad Schellevis
5fae3bcb7c
shaper, fix https://github.com/opnsense/core/pull/3213 template
2019-03-01 14:22:09 +01:00
Ad Schellevis
86a5013c15
Merge branch 'fbrendel-monit_validations'
2019-03-01 10:45:57 +01:00
Ad Schellevis
5bde17012d
Monit, minor cleanups and fixes for https://github.com/opnsense/core/pull/3155
2019-03-01 10:45:23 +01:00
Ad Schellevis
1849a3b61d
Merge branch 'monit_validations' of https://github.com/fbrendel/core into fbrendel-monit_validations
2019-03-01 10:25:55 +01:00
Franco Fichtner
81438578db
unbound: add alias support for #3260
...
Break the rules of the Dnsmasq implementation while at it:
An alias can consist of a host and/or domain and/or description.
At least a host name or a domain need to be set, the rest will be
taken from the original entry.
Missing GUI parts in the override section...
2019-03-01 08:55:50 +01:00
Ad Schellevis
2babeae771
firewall: logging for NAT rules, within the possibilities of what pf has to offer.... closes https://github.com/opnsense/core/issues/3033
2019-02-28 21:26:36 +01:00
Ad Schellevis
b214b89e20
HAsync, prevent sloppy apply behaviour in various places due to configuring the backup device and point the user to our status page.
...
- since the apply never has been complete, the current situations either results in user not knowning where their waiting for (an openvpn client for example) or users assuming all is in sync (which isn't the case)
- move restart filter action to existing sync page
closes https://github.com/opnsense/core/issues/3165
2019-02-28 18:32:17 +01:00
Ad Schellevis
b82e54fb2f
whitespace
2019-02-28 16:38:54 +01:00
Ad Schellevis
e7d04751c9
OpenVPN server, validate certificate type, closes https://github.com/opnsense/core/issues/3045
2019-02-28 16:36:40 +01:00
Ad Schellevis
6fe924c1f7
revert 7504bd00a2 since phalcon-3.4.2 fixes the earlier scope issues, closes https://github.com/opnsense/core/issues/3026
2019-02-28 16:17:44 +01:00
Ad Schellevis
21f1580348
IPsec, switch to PAM, closes https://github.com/opnsense/core/issues/3265
2019-02-28 15:32:03 +01:00
Michael Steenbeek
15ac90d94d
Remote logging: move 'enable' to the top
2019-02-28 10:43:31 +01:00
Ad Schellevis
02fd4f4c7f
Web proxy, switch to PAM, closes https://github.com/opnsense/core/issues/3261
2019-02-28 09:57:54 +01:00